Impact
An uncaught exception in SurrealDB's net module lets an authenticated user crash the database by sending a crafted HTTP contains null bytes. The exception propagates without handling, terminating the SurrealDB instance and any applications that depend on it, resulting in a denial of service and potentially taking the entire database offline.
Affected Systems
This flaw affects SurrealDB products from the SurrealDB vendor. All builds released before version 2.2.2 are vulnerable, including 2.2.1 and earlier releases. The vulnerability can only be exploited by users who have valid authentication credentials against the database.
Risk and Exploitability
The CVSS base score of 7.1 indicates a moderate to high impact, while the EPSS score of less than 1% shows a very low likelihood of widespread exploitation. The flaw is not listed in CISA's KEV catalog. Attackers would need legitimate credentials and network access to the /sql endpoint; once authenticated, the unhandled exception causes the service to crash, leading to a denial of service.
OpenCVE Enrichment